Malware Protection

Prev Next

Trellix's Endpoint Security (HX) xAgent malware protection feature guards and defends your host endpoints against malware infections by automatically scanning all files on your host endpoint for malicious code. Malware includes viruses, Trojans, worms, spyware, adware, key loggers, rootkits, and other potentially unwanted programs (PUP). Malware protection uses malware definitions to detect and identify files infected by malware. See Understanding Malware Protection for more information.

Important

Malware protection is not supported for host endpoints running Windows 2003, XP, or Vista or Windows xAgent versions 23 or earlier. See "Operating System Requirements" in the Endpoint Security (HX) Server Deployment Guide for more information about the Windows, macOS, and Linux operating systems that support Trellix Endpoint Security (HX) xAgent version 26.21.7 or later.

Malware protection has two components: malware detection and quarantine. Malware detection, which includes MalwareGuard, utilizes two scanning engines to guard and defend your host endpoints against malware infections: the Antivirus engine and the MalwareGuard engine. Quarantine isolates infected files on your endpoint and performs specific remediation actions on the infected file. See Malware Protection Overview for more information.

By default, malware protection is disabled, which means malware detection, MalwareGuard, quarantine, and remediation are also disabled by default. You can modify the xAgent default policy to enable the malware protection policy on all your host endpoints, or you can create a custom policy to enable the malware protection policy on select host sets in your environment.

You can configure malware protection policies for your host sets using the Web UI or the API. See Malware Protection Overview for more information.